Authorities Dismantle Grandoreiro Banking Malware Operation

0
[ad_1]

Group-IB, a cybersecurity firm, helped INTERPOL and Brazil dismantle the Grandoreiro banking trojan operation, as their expertise in threat intelligence and investigation was key. 

Malware samples collected during independent investigations in Brazil and Spain (2020-2022) were analyzed by Group-IB and other partners, which helped track the constantly shifting infrastructure of the attackers and pinpoint the active command and control server. 

The combined effort led to the arrest of five administrators in January 2024.

Grandoreiro, a major threat since 2017, used phishing emails mimicking legitimate organizations to target victims in Spanish-speaking countries. 

The malware steals financial data by employing a multi-pronged approach, which monitors keystrokes to capture login credentials, simulates mouse clicks for potentially fraudulent transactions, shares the victim’s screen for real-time hijacking, and displays deceptive pop-ups to trick users into compromising information.

Targeting bank accounts, the malware specifically gathers usernames and bank identifiers, granting unauthorized access, which enables criminals to completely control the victim’s account and siphon funds. 

To launder the money, they employ a money mule network, likely transferring stolen funds to Brazil and estimates suggest the malware has defrauded victims of over EUR 3.5 million, with potential losses exceeding EUR 110 million if attempted thefts were successful. 

In response to a cybercrime campaign targeting Spanish banks with Grandoreiro malware, Brazilian and Spanish authorities independently collected samples between 2020 and 2022. 

To improve their investigations, they collaborated with INTERPOL’s Cyber Crime Unit, and Group-IB, a cybersecurity firm, joined the effort to analyze the malware samples. 

Their threat intelligence and cyber investigation specialists played a key role in dissecting the Grandoreiro samples, enabling investigators to track the malware’s ever-changing network infrastructure and pinpoint the command and control server’s IP address. 

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

Brazil and Spain leverage INTERPOL’s network and expertise

In August 2023, Brazil conducted raids across five states, arresting the programmers and operators behind the Grandoreiro banking malware. 

Police officers conducting the raids
Police officers conducting the raids

INTERPOL’s Cyber Crime Unit Director, Craig Jones, emphasized the importance of information sharing in a successful cybercrime operation, highlighting INTERPOL’s role as a bridge between law enforcement and private entities in facilitating intelligence exchange. 

The collaboration paves the way for further regional cooperation against cybercrime, as INTERPOL is actively supporting ongoing investigations in Brazil, Spain, and other member countries. 

Group-IB’s investigation tracked a continuously evolving malware network infrastructure, identified the active C2 server IP, and shared it with INTERPOL to help in their operation. 

The operation resulted in the apprehension of five individuals responsible for the banking malware and court orders froze and seized assets, dismantling the criminal organization’s financial infrastructure and potentially recovering stolen funds.  

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Vivo X Fold 3 Pro price will be sky-high, details emerge

0
[ad_1]

The Vivo X Fold 3 series will arrive on March 26. That’s the launch date that Vivo scheduled for China. Some more details surfaced, and it seems like the Vivo X Fold 3 Pro price will be sky-high.

The Vivo X Fold 3 Pro price tags have been revealed and they’re… extremely high

According to a promo poster shared by Whylabs, the device is coming in two configurations. The cheaper one will include 16GB of RAM and 512GB of storage, while the top-end one will arrive with 16GB of RAM and 1TB of storage.

The two models are set to cost CNY13,999 and CNY14,999. Transferred to dollars, those price tags read $1,945 and $2,083. Needless to say, these price tags are very high.

Vivo X Fold 3 Pro price tags leak

These prices are actually extremely high for foldables in global markets, let alone in China. Chinese prices are usually considerably lower. For example, the Xiaomi 14 starts at the equivalent of $546 in China, while globally it starts at €999 ($1,092).

Its price tag in markets outside of China would be ultra-premium

You can see a huge difference here. So imagine what would the price of the Vivo X Fold 3 Pro be if it actually arrived to global markets. With such differences, we’re looking at a price tag of over $2,500 most likely. That’s actually a detail that leads us to believe it’ll stay exclusive to China.

In any case, the company already revealed the design of the Vivo X Fold 3 series. You can check out the gallery below if you’d like to take a closer look at it.

Some spec details did get revealed already

 

What we know so far is that the Snapdragon 8 Gen 3 will fuel the Vivo X Fold 3 PRo. An 8.03-inch main display was mentioned, and a 6.53-inch cover panel. Samsung’s E7 AMOLED display will be used on both ends. A 120Hz refresh rate will be on offer, and both panels will be quite bright.

Powerful cameras are also tipped, and a 5,700mAh battery. The device is also said to support 120W wired charging and 50W wireless charging. We’ll know far more on March 26.


[ad_2]
Source link

YouTube TV’s Multiview feature now available on iOS devices

0
[ad_1]

Google is working on a Multiview feature for YouTube TV and while some users benefit from having it, not everyone has access to this perk yet. Initially released on TVs, Multiview is now rolling out to iPhone and iPad, YouTube TV recently confirmed.

According to YouTube, in order to have access to Multiview, iPhone and iPad users must update the YouTube TV to version 8.11 (or a newer version).

The move doesn’t come as a surprise considering the fact that many users discovered that they received access to Multiview ahead of this week’s global rollout.

Although the iOS and TV versions of Multiview aren’t on par when it comes to functionality, at least it’s a start and Google can further improve the experience on iPhone and iPad.

As far as Android goes, it appears that Google isn’t really in a hurry to provide this feature to users of its mobile operating system. YouTube TV for Android will be getting the Multiview feature “in the coming months,” Google says, so there’s no actual ETA yet.


[ad_2]
Source link

Hackers Claimed to Breached the Israeli Nuclear Facility’s Network

0
[ad_1]

An Iranian hacker group has claimed to have infiltrated the networks of the Dimona nuclear facility located in Israel’s Negev desert.

Israeli cybersecurity teams are diligently working to verify the authenticity of the documents allegedly leaked during this cyber incident.

The details of these documents are currently under Israeli government censorship, which indicates the potential sensitivity of the information contained within them.

The leaked documents are said to encompass a range of materials, from invoices to internal correspondence, which could provide insights into the operations of one of Israel’s most secure facilities.

The full extent of the breach and the nature of the documents remain unclear as investigations continue.

Israeli Government and Cybersecurity Experts Respond

The Israeli government has not yet released an official statement regarding the breach. However, cybersecurity experts have been quick to weigh in on the situation.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

CheckPoint Software, a leading Israeli cybersecurity firm, has noted that the hackers’ tactics are consistent with previous cyberattacks attributed to Iranian groups.

These attacks often involve releasing a threatening video to instill fear and uncertainty.

Experts have also expressed skepticism about the hackers’ claims, particularly the assertion that the town of Yeruham, located less than 10 miles from the Dimona facility, should be evacuated.

The hackers ominously stated that they have “their hand on the switch,” implying a level of control that cybersecurity professionals consider to be exaggerated.

As per the report by JNS, the hackers have boasted about obtaining thousands of documents, including PDFs, emails, Excel spreadsheets, Word files, and PowerPoint presentations.

Analysis by Cybersecurity Professionals

Cybersecurity analysts have been downplaying the severity of the hack, suggesting that the documents obtained are likely unclassified and not indicative of a significant security breach.

Experts agree that the hackers’ claims are overstated and that the actual risk posed by the leaked documents may be minimal.

Nevertheless, the incident has raised concerns about the robustness of cybersecurity measures at critical infrastructure sites.

It underscores the ongoing cyber warfare between nations and the need for constant vigilance in protecting sensitive information.

As the situation unfolds, the Israeli government and cybersecurity community will continue to assess the impact of the alleged breach.

The international community will be watching closely, as the implications of such an attack could have far-reaching consequences for national security and the geopolitical landscape.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Windows Server Updates Trigger Domain Controller Failures

0
[ad_1]

Recent updates for Windows Server have been linked to significant disruptions in IT infrastructure, with numerous reports of domain controllers experiencing crashes and forced reboots.

The issues have been traced back to the March 2024 cumulative updates for Windows Server 2016 and Windows Server 2022, explicitly KB5035855 and KB5035857.

Impact on Domain Controllers

The core of the problem lies in a memory leak within the Local Security Authority Subsystem Service (LSASS), a critical component of the Windows operating system responsible for enforcing security policies and managing user logins, access token creation, and password changes.

The LSASS process is essential for the stable operation of domain controllers, which are pivotal in managing network security and user authentication within an organization’s IT environment.

Administrators have observed that domain controllers exhibit steadily increasing LSASS memory usage after installing the March updates.

This escalation in resource consumption eventually leads to the system becoming unresponsive, culminating in crashes and automatic reboots.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

Such behavior disrupts normal business operations and poses a risk to network security and data integrity.

Causes of Crashes and Reboots

The LSASS memory leak introduced by the updates is the direct cause of the crashes and reboots.

Memory leaks occur when a program incorrectly manages memory allocations, reducing performance and system stability as the available memory is gradually exhausted.

In the case of domain controllers, the LSASS process’s memory leak leads to an unsustainable load on the system, forcing a crash as a last resort to recover from the failure.

Affected Windows Server Versions

The reported issues specifically affect Windows Server 2016 and Windows Server 2022.

These versions are widely used in enterprise environments, meaning the impact of the problem is potentially vast, affecting organizations globally.

This is not the first time LSASS-related issues have been reported after Windows Server updates—previous incidents were recorded in December 2022 and March 2022—which raises concerns about the recurring nature of such critical vulnerabilities.

The sysadmin community has been vocal about the disruptions, with many taking to online forums such as Reddit to share their experiences and seek advice. Comments range from frustration over the repeated nature of these issues to concerns about the lack of immediate solutions or workarounds.

Some users have reported rolling back the updates as a temporary fix, while others are waiting for Microsoft’s official response or patch.

A particular comment on the Microsoft Tech Community Exchange Team Blog highlights the severity of the issue, with one user stating, “This is a disaster. We’ve had to roll back the updates on all our DCs to prevent the entire network from going down.”

LSASS Process Memory Leak

The LSASS process memory leak is not new, but its recurrence is troubling for Microsoft and its user base.

The memory leak leads to a gradual increase in memory usage by the LSASS process until the system can no longer function properly. This type of issue requires prompt attention and resolution to maintain the security and stability of affected systems.

Microsoft has not released an official statement or solution regarding the March 2024 updates and the resulting domain controller crashes.

This situation underscores the importance of thorough testing and quality assurance in software updates, mainly when they affect critical components of enterprise IT infrastructure.

As the situation develops, system administrators are advised to monitor official channels for updates and consider holding off on applying the problematic updates until a fix is confirmed.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

This is why you need a VPN on your devices

0
[ad_1]

We all know that it’s not particularly safe to join a public Wi-Fi network, where hackers and snoops can easily access your private data and wreak havoc with your devices.

What many of us don’t realize, however, is that browsing at home on our own secure Wi-Fi connections isn’t that much safer—at least, not if you don’t have a VPN like Surfshark installed.

If you’re not yet up to speed on this essential feature of modern internet security, a VPN—which stands for “Virtual Private Network”—uses encryption and anonymous servers to shield your internet data from prying eyes.

The technology behind VPNs is complicated, but in a nutshell, it replaces your IP address—a highly specific string of numbers denoting your real-world location, ISP, and a whole lot more—with an address linked to a server used anonymously by thousands of other people.

Without a VPN, collecting your data is about as difficult for a hacker as looking you up in the Yellow Pages. With a VPN, you’re about as easy to find as a specific water molecule in the Pacific ocean.

Internet security is the main reason that most users install a VPN. It lets them browse the internet safely and privately, even when their devices are connected to public wi-fi, where “man in the middle” attacks are commonplace.

But they do so much more.

For a start, a VPN lets you avoid those creepy targeted ads that seem to know exactly how old you are, where you live, and what kind of stuff you like to buy.

If marketers don’t know who you are, they can’t get all up in your face with quasi-personalized recommendations, leaving you free to make your own mind up in peace.

Then there’s the question of censorship and regional restrictions. The internet isn’t the same place for every country in the world, with many governments blocking certain types of content for political reasons.

Multiplatform iOS + macOS + TV

Likewise, companies often restrict the flow of content by region for commercial reasons. Ever tried Canadian Netflix? It’s a blast, and only people in Canada get to enjoy it.

A VPN lets you get around this problem by simply connecting your computer to an anonymous server in Canada.

Or, if you live in Canada but happen to be on holiday elsewhere, a VPN lets you connect with your native land and access your region-locked banking apps, local news services, and, yes, Netflix.

Plus, a VPN gives you access to region-locked video game betas, YouTube content, and much more.

Which, by the way, is not an invitation to do anything illegal online, safe in the knowledge that you won’t be caught. The terms of service for VPNs like Surfshark insist that users comply with all applicable laws—so behave yourself.

Security and access to restricted content are two of the best reasons to start using a VPN, but the list doesn’t stop there.

A VPN also solves the problem of ISP throttling, by preventing your ISP from knowing where traffic on its network is coming from. And you can use a VPN to get the best deals since the prices of products and services often vary by region.

If you’re looking to join the VPN movement, you could do a lot worse than take advantage of Surfshark’s current 83% off + two months free offer.

Surfshark is an award-winning option, and right now it’s an absolute steal.


[ad_2]
Source link

Neuralink’s brain-chip patient is playing Civilization VI for 8 hours straight with his mind

0
[ad_1]

In 2024, we may not have the flying cars people in the 1950s envisioned, but we already have a human with a chip installed in its brain that’s allowing him to do incredible stuff.

Like playing chess, and playing Civilization VI for 8 hours straight – all just by thinking about it, without actually interacting with the games’ interface.

Reuters reports the latest developments on Neuralink’s first brain-chip patient: 29-year-old Noland Arbaugh.

Neuralink is a neurotechnology company founded by Elon Musk with the goal of developing implantable brain–machine interfaces (BMIs). Its primary aim is to enable humans to communicate directly with computers and to enhance cognitive capabilities, potentially offering solutions for neurological conditions and integrating artificial intelligence with human cognition.

Also, Neuralink – and companies alike – is what gives many people nightmares. Yup, misuse of technology can and does happen, so brace yourselves.

Back to Neuralink’s first brain-chip patient, though. Neuralink livestreamed the patient using only his mind to play online chess.

Noland Arbaugh was paralyzed below the shoulder after a diving accident, and is now able to play chess on his laptop. The implant seeks to enable people to control a computer cursor or keyboard using only their thoughts.

“The surgery was super easy. I literally was released from the hospital a day later. I have no cognitive impairments. I had basically given up playing that game,” Arbaugh said, referring to the game Civilization VI, “you all (Neuralink) gave me the ability to do that again and played for 8 hours straight.”

In January, Neuralink implanted the chip in his brain, after receiving approval for human trial recruitment in the Fall of 2023. Back in 2022, the Neuralink project entered its human trial phase – prior to that, Neuralink carried out testing with primates, killing 15 of the 23 test monkeys.

Now, the patient zero with a brain chip appears to have fully recovered. This is great, but it’s remarkable that the patient is able to control a computer mouse using their thoughts, the startup’s founder Elon Musk said a month ago.

“Progress is good, and the patient seems to have made a full recovery, with neural effects that we are aware of. Patient is able to move a mouse around the screen by just thinking”, Musk said.


[ad_2]
Source link

GitHub’s New AI Tool that Fixes Your Code Automatically

0
[ad_1]

GitHub has leaped application security by introducing a new feature that promises to revolutionize how developers address code vulnerabilities.

The new tool, code scanning autofix, is now available in public beta for all GitHub Advanced Security customers, harnessing the power of GitHub Copilot and CodeQL to offer unprecedented assistance in code remediation.

Found Means Fixed: A Vision for Application Security

GitHub’s vision for application security is encapsulated in the principle that “found means fixed.”

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

With the introduction of code scanning autofix, GitHub is making strides towards an environment where the discovery of a vulnerability is immediately followed by its resolution.

This tool is not just a theoretical advancement; it is a practical solution that has been shown to help teams remediate issues up to seven times faster than traditional security tools.

Github Advanced Security (source:Github)
Github Advanced Security (source:GitHub)

How Code Scanning Autofix Works

Code scanning auto-fix is designed to provide developers with an explanation and code suggestions to remediate a vulnerability.

This feature covers over 90% of alert types in popular programming languages such as JavaScript, TypeScript, Java, and Python.

It can deliver code suggestions that can remediate more than two-thirds of found vulnerabilities with minimal editing required by the developer.

Github Advanced Security

Addressing Application Security Debt

Applications are a leading attack vector, and many organizations acknowledge the challenge of managing an increasing number of unremediated vulnerabilities in production repositories.

Code scanning autofix aims to curb the growth of this “application security debt” by simplifying the process for developers to fix vulnerabilities as they arise during coding.

Just as GitHub Copilot has been assisting developers by automating tedious and repetitive tasks, code scanning auto-fix is set to help development teams save valuable time previously spent on remediation.

Security teams also benefit from this tool as it reduces the volume of everyday vulnerabilities, allowing them to concentrate on higher-level strategies to safeguard the business in a fast-paced development environment.

The Technology Behind Autofix

The magic behind code scanning auto-fix lies in the CodeQL engine, which, in combination with heuristics and GitHub Copilot APIs, generates code suggestions.

When a vulnerability is detected in a supported language, the tool provides a natural-language explanation of the fix and a preview of the code suggestion.

Developers can then choose to accept, edit, or dismiss the suggestion. These suggestions can span multiple files and include necessary changes to project dependencies.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

The Pixel market share is nearing 5% in the US

0
[ad_1]

We are knee-deep into Q1 2024, so we are starting to see numbers trickling in from Q4 2023. We’re able to get a glimpse at how smartphone companies performed during the final three months of the year. Well, it looks like Google has caused to celebrate because Pixel phones are nearing 5% of the US market in terms of market share.

Right now, the global smartphone market is facing some challenges with stagnated growth due to the poor economic situation. However, several companies are seeing varying degrees of success in the smartphone market. For example, the Galaxy S24 series of phones seems to be doing pretty well for Samsung. These phones are breaking sales records for the company.

Pixel phones are nearing 5% market share in the US

The top three spots in the US smartphone market are pretty much set in stone. Apple (51.9%) is in first place by a large margin, Samsung (22.4%) is in second place, and Motorola (8%) is in third. It will take an act of cosmic proportions to move any of these three heavy hitters from their spots. However, the lower spots fluctuate much more frequently. According to a new report from IDC, the Google Pixel phone is starting to near the 5% mark in terms of market share for the US. The number might not seem significant in the grand scheme of things, but it shows that Pixel phones are rising at a steady rate in the US. Sure, Pixel phones are extremely popular in Japan, but the US is Google’s home.

Looking at the numbers, Google was able to tackle 4.6% of the US smartphone market in Q4 2023. All of this is despite a heavy 13.6% decline in YoY shipments for the same quarter. Pixels were able to secure fourth place in the US in terms of market share, just beating out TCL’s 4.2%.

Below TCL, we have the rest of the riffraff, the dreaded “Other” category. This section of the market made up 8.6% of the US smartphone market share.

As for the smartphone market as a whole, it shrank by an unfortunate 6.9% YoY. There were 130.6 million units shipped during the last 3 months of 2023.

Unlocked phones

Google was also able to sell a significant amount of unlocked phones in the US last quarter. According to the numbers, Motorola was able to make up 34% of the total number of unlocked phones sold in the US, and that gave it the top spot. In second place, with 20%, we have Samsung with Apple following it closely with 19%. In fourth place, we have Google with 9% of the market. That’s pretty significant. Under Google, we have TCL with 6%.

With this news, we’re certain that Google is celebrating and planning on pushing its market share even further in the coming year.


[ad_2]
Source link

Apple reportedly will get sued by DOJ Thursday; tech rivals say Apple failed to follow judge’s orders

0
[ad_1]
The U.S. Department of Justice is ready to file a lawsuit against Apple as soon as tomorrow. The suit would charge Apple with violating antitrust laws by blocking the company’s rivals from accessing certain hardware and software features of the iPhone. The news of the suit, which will be filed in federal court, was first published by Bloomberg on Wednesday. While Apple has been sued by the DOJ two other times over the past 14 years, this suit is a little different since it accuses Apple of using illegal methods to help the iPhone dominate in certain markets.
Back in January, we told you that the DOJ was on the verge of filing this lawsuit which charges Apple with making it difficult for rival firms to compete against the iPhone. At the time, some of the issues that were mentioned by The New York Times included Apple’s decision to lock competitors out of its iMessage platform, why the Apple Watch works better with the iPhone than other smartphones, and how Apple’s mobile payment system blocks third-party firms from competing with Apple.

Some of these issues were addressed in the EU with the passage of the Digital Markets Act (DMA) which requires Apple in the 27 EU countries to allow the use of third-party in-app payment platforms, requires Apple to allow third-party financial firms to work with the iPhone’s mobile-payment system, and opens up the iPhone to non-WebKit-powered mobile browsers. Last month, Bloomberg reported that Apple met with officials from the DOJ in an effort to convince the agency not to file an antitrust lawsuit. If Bloomberg is correct about what is coming on Thursday, Apple failed.

Developers can now put a single link in their app directing customers to third-party payment processing platforms. However, Apple is still collecting a cut of 12% to 27% on these purchases, 3 percentage points less than the 15%-30% cut Apple takes for transactions going through its own in-app payment processing platform. 

Epic is complaining about the fee Apple still charges even when third-party payment platforms are used. The game developer is also not happy about the one link limit that the tech giant allows and says that the iPhone maker should be held in contempt of court. Microsoft, Meta, X, and Match say that Apple is preventing apps from including “even the most basic information” about third-party payment platforms. Apple claims that it has been in compliance with the judge’s order since January.

 

Apple’s shares have been on the rebound lately rising from $170 to nearly $179 in line with a strong tech sector. However, once the Bloomberg report came out, the shares got hit in after-hours trading declining to $176.40.


[ad_2]
Source link